Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 2.1

    LOW
    CVE-2004-0075

    The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service.... Read more

    Affected Products : linux_kernel
    • EPSS Score: %0.07
    • Published: Mar. 15, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1358

    The patches (1) 114332-08 and (2) 114929-06 for Sun Solaris 9 disable the auditing functionality of the Basic Security Module (BSM), which allows attackers to avoid having their activity logged.... Read more

    Affected Products : solaris
    • EPSS Score: %0.54
    • Published: Mar. 12, 2004
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2003-1199

    Cross-site scripting (XSS) vulnerability in MyProxy 20030629 allows remote attackers to inject arbitrary web script or HTML via the URL.... Read more

    Affected Products : myproxy
    • EPSS Score: %1.16
    • Published: Mar. 11, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-1770

    The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user parameter.... Read more

    Affected Products : cpanel
    • EPSS Score: %11.89
    • Published: Mar. 11, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-1769

    The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackers to execute arbitrary code via the user parameter to resetpass.... Read more

    Affected Products : cpanel
    • EPSS Score: %4.39
    • Published: Mar. 11, 2004
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2004-1359

    Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uucp user.... Read more

    Affected Products : solaris sunos
    • EPSS Score: %0.09
    • Published: Mar. 04, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0008

    Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.... Read more

    Affected Products : linux gaim ultramagnetic
    • EPSS Score: %19.18
    • Published: Mar. 03, 2004
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2004-0115

    VirtualPC_Services in Microsoft Virtual PC for Mac 6.0 through 6.1 allows local attackers to truncate and overwrite arbitrary files, and execute arbitrary code, via a symlink attack on the VPCServices_Log temporary file.... Read more

    Affected Products : virtual_pc
    • EPSS Score: %1.08
    • Published: Mar. 03, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-0040

    Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 4200 allows remote attackers to execute arbitrary code via an ISAKMP packet with a large Certificate Request packet.... Read more

    Affected Products : vpn-1 firewall-1 vpn-1_firewall-1
    • EPSS Score: %25.88
    • Published: Mar. 03, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-0039

    Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server included with NG FP1, FP2, and FP3 allows remote attackers to execute arbit... Read more

    Affected Products : firewall-1 vpn-1_firewall-1
    • EPSS Score: %41.48
    • Published: Mar. 03, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0127

    Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execute arbitrary PHP programs on the server via .. (dot dot) sequences in the gedcom_config parameter.... Read more

    Affected Products : phpgedview
    • EPSS Score: %1.33
    • Published: Mar. 03, 2004
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2004-0099

    mksnap_ffs in FreeBSD 5.1 and 5.2 only sets the snapshot flag when creating a snapshot for a file system, which causes default values for other flags to be used, possibly disabling security-critical settings and allowing a local user to bypass intended ac... Read more

    Affected Products : freebsd
    • EPSS Score: %0.07
    • Published: Mar. 03, 2004
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2004-0089

    Buffer overflow in TruBlueEnvironment in Mac OS X 10.3.x and 10.2.x allows local users to gain privileges via a long environment variable.... Read more

    Affected Products : mac_os_x mac_os_x
    • EPSS Score: %0.16
    • Published: Mar. 03, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0080

    The login program in util-linux 2.11 and earlier uses a pointer after it has been freed and reallocated, which could cause login to leak sensitive data.... Read more

    Affected Products : util-linux
    • EPSS Score: %1.61
    • Published: Mar. 03, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0009

    Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.... Read more

    Affected Products : apache-ssl
    • EPSS Score: %0.75
    • Published: Mar. 03, 2004
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2004-0003

    Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."... Read more

    Affected Products : linux_kernel
    • EPSS Score: %0.09
    • Published: Mar. 03, 2004
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2004-0114

    The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a shared memory segment's reference count when the vm_map_find function fails, whic... Read more

    Affected Products : freebsd netbsd openbsd
    • EPSS Score: %0.33
    • Published: Mar. 03, 2004
    • Modified: Apr. 03, 2025
  • 9.8

    CRITICAL
    CVE-2004-0005

    Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal encoding in yahoo_decode that causes a null byte to be written beyond the buffer, (2) octal encoding in yahoo_deco... Read more

    Affected Products : gaim
    • EPSS Score: %21.42
    • Published: Mar. 03, 2004
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2004-0087

    The System Configuration subsystem in Mac OS 10.2.8 and 10.3.2 allows local users to modify network settings, a different vulnerability than CVE-2004-0088.... Read more

    Affected Products : mac_os_x mac_os_x
    • EPSS Score: %0.09
    • Published: Mar. 03, 2004
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2004-0088

    The System Configuration subsystem in Mac OS 10.2.8 allows local users to modify network settings, a different vulnerability than CVE-2004-0087.... Read more

    Affected Products : mac_os_x mac_os_x
    • EPSS Score: %0.08
    • Published: Mar. 03, 2004
    • Modified: Apr. 03, 2025
Showing 20 of 291741 Results